{"id":981,"date":"2026-08-23T21:44:43","date_gmt":"2026-08-23T21:44:43","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=981"},"modified":"2026-08-23T21:44:43","modified_gmt":"2026-08-23T21:44:43","slug":"ciso","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/ciso\/","title":{"rendered":"CISO (Chief Information Security Officer)"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CISO (CHIEF INFORMATION SECURITY OFFICER)\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A CISO is the person accountable for information security across an organisation, and in a growing number of sectors the role is no longer optional but written into regulation.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Governance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A CISO, or Chief Information Security Officer, owns security risk for the business. The role covers policy, risk assessment, compliance mapping, incident response, vendor risk and reporting to the board. It is a governance role rather than an engineering one. Indian financial regulators now require regulated entities to designate a CISO, and enterprise buyers ask who holds the role long before any regulator does. Small companies rarely hire one. They assign the accountability and buy the capability.<\/p>\n<\/div>\n\n<p>The word most people miss in that definition is accountable. The role is not about configuring the firewall. It is about answering for whether it was configured correctly.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What a CISO actually does<\/a><\/li>\n    <li><a href=\"#mandatory\">When a CISO becomes mandatory<\/a><\/li>\n    <li><a href=\"#versus\">CISO, Chief Technology Officer and engineer<\/a><\/li>\n    <li><a href=\"#lean\">What lean teams do instead<\/a><\/li>\n    <li><a href=\"#osto\">How Osto covers the CISO workload<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What a CISO actually does<\/h2>\n\n<p>The role is often described as technical leadership, which undersells it. Most of the work is translation: turning technical reality into risk the board can act on, and turning regulation into controls engineers can build.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 290\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The CISO reports to the board and owns governance, risk, compliance, operations and third-party security domains.\">\n  <defs><marker id=\"ciA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"284\" y=\"14\" width=\"192\" height=\"46\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"380\" y=\"43\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#6b4576\">Board or founders<\/text>\n\n  <line x1=\"380\" y1=\"62\" x2=\"380\" y2=\"82\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n\n  <rect x=\"284\" y=\"88\" width=\"192\" height=\"52\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"380\" y=\"112\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">CISO<\/text>\n  <text x=\"380\" y=\"130\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Accountable for security risk<\/text>\n\n  <line x1=\"380\" y1=\"142\" x2=\"380\" y2=\"160\" stroke=\"#4a52a8\" stroke-width=\"2.5\"\/>\n  <line x1=\"86\" y1=\"160\" x2=\"674\" y2=\"160\" stroke=\"#4a52a8\" stroke-width=\"2.5\"\/>\n  <line x1=\"86\" y1=\"160\" x2=\"86\" y2=\"180\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n  <line x1=\"233\" y1=\"160\" x2=\"233\" y2=\"180\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n  <line x1=\"380\" y1=\"160\" x2=\"380\" y2=\"180\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n  <line x1=\"527\" y1=\"160\" x2=\"527\" y2=\"180\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n  <line x1=\"674\" y1=\"160\" x2=\"674\" y2=\"180\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#ciA)\"\/>\n\n  <rect x=\"16\" y=\"186\" width=\"140\" height=\"58\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"86\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Policy and<\/text>\n  <text x=\"86\" y=\"225\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">governance<\/text>\n\n  <rect x=\"163\" y=\"186\" width=\"140\" height=\"58\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"233\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Risk and<\/text>\n  <text x=\"233\" y=\"225\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">compliance<\/text>\n\n  <rect x=\"310\" y=\"186\" width=\"140\" height=\"58\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"380\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6a89\">Security<\/text>\n  <text x=\"380\" y=\"225\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6a89\">operations<\/text>\n\n  <rect x=\"457\" y=\"186\" width=\"140\" height=\"58\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"527\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Incident<\/text>\n  <text x=\"527\" y=\"225\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">response<\/text>\n\n  <rect x=\"604\" y=\"186\" width=\"140\" height=\"58\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"674\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#6b4576\">Third-party<\/text>\n  <text x=\"674\" y=\"225\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#6b4576\">risk<\/text>\n\n  <rect x=\"16\" y=\"256\" width=\"728\" height=\"26\" rx=\"11\" fill=\"#eef0f4\"\/>\n  <text x=\"380\" y=\"274\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#0f1538\">Regulators expect the reporting line to sit outside the team that builds and ships the systems.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>In a small company one person may cover every box. The accountability still has to be named.<\/figcaption>\n<\/figure>\n\n<h2 id=\"mandatory\" class=\"c-sage\">When a CISO becomes mandatory<\/h2>\n\n<p>For most startups the trigger is commercial before it is legal. A security questionnaire asks who owns security, and a blank answer stalls the deal. In regulated sectors the requirement is explicit.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Trigger<\/th><th>What it requires<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>RBI Information Technology Governance Directions<\/td><td>A designated CISO at banks and at non-banking financial companies in the Middle, Upper and Top <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nbfc-regulatory-layers\/\">NBFC regulatory layers<\/a>, with a defined reporting line<\/td><\/tr>\n    <tr><td>Payment system operator licences<\/td><td>Board-approved information security governance, which in practice means a named owner<\/td><\/tr>\n    <tr><td>Securities and insurance regulators<\/td><td>Cyber security frameworks for market intermediaries and insurers designate an accountable security officer<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and SOC 2<\/td><td>No CISO title is mandated, but roles and responsibilities must be assigned and evidenced<\/td><\/tr>\n    <tr><td>Enterprise procurement<\/td><td>Vendor questionnaires and due diligence ask for a named security contact and an escalation path<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"versus\" class=\"c-apri\">CISO, Chief Technology Officer and security engineer<\/h2>\n\n<p>These get collapsed into one another constantly, usually because one person is doing all three.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Role<\/th><th>Owns<\/th><th>Problem when merged<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>CISO<\/strong><\/td><td>Security risk, policy, compliance posture, board reporting<\/td><td>Loses independence if buried inside engineering<\/td><\/tr>\n    <tr><td><strong>CTO<\/strong><\/td><td>Technology strategy and delivery<\/td><td>Shipping speed and security assurance pull in opposite directions on the same calendar<\/td><\/tr>\n    <tr><td><strong>Security engineer<\/strong><\/td><td>Building and running controls<\/td><td>Cannot audit their own work, and does not sit close enough to the board<\/td><\/tr>\n    <tr><td><strong>Fractional or virtual CISO<\/strong><\/td><td>The governance layer, part-time and external<\/td><td>Needs real platform data underneath, or it becomes documentation with nothing behind it<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Why regulators care about the reporting line<\/p>\n  <p>The requirement is rarely just that a CISO exists. It is that the CISO can raise an uncomfortable finding without it being overruled by the person whose release it would delay. That is why the directions talk about where the role reports, not only whether the title has been filled.<\/p>\n<\/div>\n\n<h2 id=\"lean\">What lean teams do instead<\/h2>\n\n<p>A full-time CISO is a senior hire, and most companies at seed or Series A cannot justify one against an engineering role. The workable pattern has three parts.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Name the accountability<\/p>\n    <p>Usually a founder or the head of engineering, written down, with the escalation path documented. Unnamed ownership fails questionnaires immediately.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Buy the capability<\/p>\n    <p>Testing, monitoring, posture management and evidence collection run on a platform rather than depending on someone&#8217;s available hours.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Rent the judgement<\/p>\n    <p>Fractional or virtual CISO support for the audit-facing and board-facing work, without carrying a full-time salary.<\/p>\n  <\/div>\n<\/div>\n\n<p>What does not work is treating the title as the deliverable. Appointing someone with no tooling, no <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> process and no evidence trail produces an org chart entry and nothing a reviewer can rely on.<\/p>\n\n<h2 id=\"osto\" class=\"c-plum\">How Osto covers the CISO workload<\/h2>\n\n<p>Most of the work a security leader coordinates gets scattered across ten separate tools. Osto runs it in one stack by default. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and continuous scanning cover the testing programme, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlated logging<\/a> cover monitoring and detection, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a> and access controls cover the identity baseline. Because every module sits in the same stack, the reporting a CISO would otherwise assemble by hand comes out of one dashboard.<\/p>\n\n<p>The compliance layer is purpose-built for the governance half. Controls map to <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-for-startups\/\" target=\"_blank\" rel=\"noopener\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> and Indian sectoral frameworks from the same evidence, so one person can hold the role credibly without a team behind them. Osto prepares your evidence and gets you through the review. Where an audit is mandated, it is performed by the accredited or <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/\">CERT-In empanelled auditor<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Security leadership without the headcount<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs the testing, monitoring, posture and evidence a security programme needs, in one platform. Your named owner gets a dashboard instead of a second job.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; SOC 2, ISO 27001 and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does a CISO do?<\/summary>\n  <p>A CISO owns information security risk for the organisation. That covers security policy, risk assessment, compliance posture, security operations oversight, incident response, third-party risk and reporting to the board. The role is accountable for outcomes rather than responsible for implementation.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a CISO and a Chief Technology Officer?<\/summary>\n  <p>The Chief Technology Officer owns technology strategy and delivery. The CISO owns security risk and assurance over that technology. Merging the two creates a conflict, because the same person judges whether their own delivery decisions were safe. Regulators focus on the reporting line for this reason.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a startup need a CISO?<\/summary>\n  <p>Rarely as a full-time hire before scale, but almost always as named accountability. Enterprise security questionnaires and due diligence ask who owns security and how issues escalate. A blank answer stalls deals. Most small teams assign the role internally and support it with a platform and fractional expertise.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a CISO legally required in India?<\/summary>\n  <p>In regulated sectors, yes in substance. The RBI Information Technology Governance Directions require banks and non-banking financial companies in the Middle, Upper and Top Layers to designate a CISO with a defined reporting line, and securities and insurance regulators set comparable expectations. There is no general requirement across all companies.<\/p>\n<\/details>\n\n<details>\n  <summary>What is a virtual CISO?<\/summary>\n  <p>An external, part-time arrangement that supplies the governance and board-facing work of the role without a full-time hire. It fits companies that need credible security leadership for audits and customer reviews but do not yet have the scale to justify the salary. It works only when real platform data sits underneath it.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> ISMS &middot; ISO 27001 &middot; Risk Assessment &middot; Risk Treatment Plan &middot; Statement of Applicability &middot; SIEM &middot; VAPT &middot; NBFC Regulatory Layers<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A CISO is the person accountable for information security across an organisation, and in a growing number of sectors the\u2026<\/p>\n","protected":false},"author":8,"featured_media":982,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[438,437],"class_list":["post-981","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-chief-information-security-officer","tag-ciso"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=981"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/981\/revisions"}],"predecessor-version":[{"id":983,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/981\/revisions\/983"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/982"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}